2025–2026 QualDerm Partners — ~3.1M individuals (HHS; dermatology MSO network intrusion)
Data compromised
Names, DOB, emails, MRNs, diagnoses/treatment, insurance, provider info, government IDs (some individuals)
Technical writeup
QualDerm Partners, LLC, a Tennessee-based management services organization for dermatology practices, disclosed unauthorized network access in late December 2025 (public timelines often cite December 23–24, 2025 activity with discovery December 24, 2025). The U.S. Department of Health and Human Services Office for Civil Rights breach portal listed the incident affecting approximately 3,117,874 individuals (~3.1M), a figure repeatedly echoed in March 2026 legal and trade reporting. Data types described in public reporting included medical records, diagnoses, health insurance information, government-issued IDs, names, dates of birth, email addresses, medical record numbers, treatment information, provider names, and in some cases driver's license numbers. QualDerm offered identity and credit monitoring and engaged forensic specialists and regulators per disclosure summaries.
Root cause
Unauthorized network/system access; technical details limited in public disclosures
References
- https://www.securityweek.com/3-1-million-impacted-by-qualderm-data-breach/
- https://securityaffairs.com/189917/data-breach/qualderm-partners-december-2025-data-breach-impacts-over-3-million-people.html
- https://www.globenewswire.com/news-release/2026/03/24/3261870/0/en/Data-Breach-Alert-Edelson-Lechtzin-LLP-Investigates-QualDerm-Partners-LLC-Data-Breach-Affecting-More-Than-3-Million-Individuals.html